Skip to main content
CoreFolioHIPAA
Tools

How much does a HIPAA risk assessment cost?

A HIPAA risk assessment costs $0 to about $8,000 depending on who does the work. Here is what each path costs — and where guided software fits.

By CoreFolio

5-minute read

A HIPAA risk assessment costs a small practice between $0 and about $8,000 in 2026: nothing but your time with the free government tool, around $1,200 per year for all-in guided software, or $1,500–$8,000 for a consultant-led assessment. The price depends far less on your practice size than on how much of the work you keep in-house. ("Risk assessment," "risk analysis," and "security risk assessment" all name the same work required by 45 CFR § 164.308(a)(1)(ii)(A).1)

The short answer

For a small practice in 2026, a HIPAA risk assessment costs anywhere from $0 to about $8,000, depending on who does the work:

  • The free government tool — $0, plus your own time.
  • Self-service guided software — around $1,200 per year for a comparable, all-in feature set, with the documentation included.
  • A consultant — about $1,500 to $8,000 for the assessment alone, or $5,000 to $15,000 for a full first-year program.2

What you are actually paying for

Office for Civil Rights (OCR) does not charge a fee for a risk analysis and does not tell you how to produce one — only that it be accurate, thorough, and current.1 So the cost is about the method you choose, plus two costs that never appear on an invoice:

  • Your time — the hours spent inventorying systems, rating risks, and writing the documentation.
  • The risk of getting it wrong — an assessment that misses systems or uses the wrong method can fail when OCR reviews it. A quote under $1,000 is often a checklist, not the analysis the rule requires.

The free government tool

The U.S. Department of Health and Human Services (HHS) Security Risk Assessment Tool is free and follows a recognized structure. It is a reasonable starting point if you have the regulatory knowledge, a simple single-location setup, and the time to interpret the output yourself. The trade-off: it produces a report you have to read and act on alone, with no remediation guidance and no help keeping the document current next year.

Self-service guided software

This is the middle path — and for many small practices, the best value. Guided software asks plain-English questions, structures the output to the method OCR expects (NIST SP 800-30) and produces the documentation for you.3 Watch the headline price, though: the lowest advertised rates usually cover the assessment only. Once you add the pieces a defensible file actually needs — policies, staff training, and vendor tracking — a comparable, all-in subscription runs about $1,200 per year.2

Within this category, there is an important split: whether the software hands you documents to maintain, or keeps a file that maintains itself. That is where CoreFolio is different — more on that below.

A consultant

A consultant does the work for you and, at the higher end, includes an on-site review and a tailored plan. Expect about $1,500 to $8,000 for the assessment alone, or $5,000 to $15,000 for a full first-year program that also fixes gaps and writes policies.2 This is the right path for a complex or multi-location environment, or a post-incident situation where OCR may already be involved — a strong fit at a different price point. It costs the most in dollars, and annual updates usually mean re-engaging.

A simple comparison

PathTypical costTime to done
Free HHS tool$0Hours to days, on your own
Self-service guided softwareAbout $1,200/year, all-inAbout an hour
Consultant$1,500–$8,000 (assessment)Weeks

A living binder, not a one-time document set

Most ways of doing this — the free tool, downloaded template libraries, even software that uses AI to draft your policies — leave you with documents you generate once and then keep current by hand. The moment your practice changes, the file starts drifting from reality, and updating each document is a chore that tends to fall to whoever has the least time.

CoreFolio HIPAA works differently. You enter your practice once — your systems, vendors, locations, and staff — and your documents are built from those details. Your dated Risk Analysis Report and Risk Management Plan — the two documents OCR names in its settlements — and the supporting policies read like they were written for your practice, with vendor scripts tailored to your specific EHR. When something changes — a new vendor, another location, a staff update — the binder flags the documents that need a refresh, so what you hand an auditor reflects your practice today, not the day you first filled it in.

That is the difference between buying a set of documents and keeping a living file — and it is still self-service software built for a practice without a compliance team: about an hour to complete, on any device, one flat price with no sales call. It is $99/month or $990/year, less than a comparable all-in software bundle and a fraction of a consultant engagement. The first 100 founding practices lock in $49/month or $490/year for as long as they stay subscribed, a limited offer while those founding seats last.

The cost of getting it wrong

OCR's Risk Analysis Initiative settlements for small practices have landed in the low five figures and up, usually paired with a multi-year corrective action plan.4 Against that, a few hundred to a few thousand dollars for a defensible, dated analysis is inexpensive insurance. The question is not only "what does this cost?" but "what does it cost if the analysis does not hold up?"

How to choose

  • Choose the free tool if you have the regulatory knowledge, a simple setup, and time to interpret the output yourself.
  • Choose self-service guided software if you want a defensible, dated document and documentation that stays current — at a flat annual price, without a consultant engagement.
  • Choose a consultant if your environment is complex or multi-site, or you are post-incident and want expert hands on the work.

Budgeting for your whole HIPAA program rather than the assessment alone? See how much HIPAA compliance costs.

Sources

Footnotes

  1. 45 CFR § 164.308(a)(1)(ii)(A) (risk analysis requirement). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308 2

  2. Cost ranges based on published vendor pricing and consultant market rates as of 2026. Individual quotes vary by scope, location, and complexity. 2 3

  3. NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments. https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

  4. HHS OCR resolution agreements and civil monetary penalties, including the Risk Analysis Initiative. https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html